01
Verify the person
Confirm the user through an approved channel before changing credentials, authentication methods, forwarding, or mailbox settings.
Everyday IT · Security
When a user reports an MFA prompt they did not initiate, an unfamiliar sign-in, or suspicious mailbox behavior, switch from routine authentication troubleshooting to evidence-driven first response.Do not weaken MFA to make the symptom disappear.
Preserve security while you determine whether the activity is expected, stale, or malicious.
01
Confirm the user through an approved channel before changing credentials, authentication methods, forwarding, or mailbox settings.
02
Capture the approximate time, device, location, application, prompt type, and whether the user initiated a sign-in at that moment.
03
Look for unfamiliar devices, locations, impossible timing, repeated failures, risk indicators, or authentication events that do not match the user's explanation.
04
If compromise is plausible, review suspicious forwarding, inbox rules, delegates, recovery methods, and other account changes using the approved security process.
05
Use the organization's approved response path for password reset, session revocation, method recovery, or account restriction. Do not improvise broad tenant changes.
06
Hand off the exact event, what is confirmed, what changed, containment already performed, and what remains unknown.
A suspicious prompt is not evidence that MFA is the problem.
Removing authentication methods without understanding ownership and recovery can make the incident harder to contain.
The legitimate user being able to sign in does not rule out another active session or account change.
Administrator, finance, executive, or shared-service identities deserve a lower threshold for formal incident handling.
Unexpected authentication activity changes the ticket from “make login work” to “prove who is signing in.”
Keep the next action inside the approved security process.
Scope
Separate one prompt or identity from a pattern involving multiple users, devices, locations, or services. Scope the problem
Change
Before resetting credentials, revoking sessions, or changing authentication methods, define authority, impact, and rollback. Plan the change safely
Escalate
If compromise is plausible or the identity is privileged, preserve the timeline, findings, containment state, and exact unresolved risk. Escalate with evidence